Apache.Struts.2.File.Upload.DoS
Description
This indicates an attack attempt to exploit a Denial of Service Vulnerability in Apache Software Foundation Struts.
The vulnerability is due to insufficient input validation leading to incorrect file permissions set on file upload. A remote attacker can exploit this vulnerability by sending a crafted HTTP request containing a malicious parameter to a vulnerable server. Successful exploitation will result in denial of service conditions on the file upload functionality.
Affected Products
Apache Software Foundation Struts 2.0.0 through 2.5.20
Impact
Denial of Service: Remote attackers can crash vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://cwiki.apache.org/confluence/display/ww/s2-060
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-10-08 | 16.940 | Default_action:pass:drop |
2020-09-24 | 16.932 | Name:Apache. Struts2. File. Upload. DoS:Apache. Struts. 2. File. Upload. DoS |
2020-09-14 | 16.922 |